Kubernetes Interview Mock sample questions with answers

10 questions from the Kubernetes Interview Mock practice bank, spread across its domains. Pick your answer, then open the explanation to see why each option is right or wrong.

  1. Question 1Running Applications

    Every Pod in namespace ci must pull images from a private registry, and you don't want to edit every Pod spec. What is the cleanest approach?

    • A

      Add the credentials to a ConfigMap read by the container runtime

    • B

      List the Secret in the ServiceAccount's imagePullSecrets

    • C

      Mount the Secret at /root/.docker/config.json in every container

    • D

      Set imagePullPolicy: Always, which makes the kubelet authenticate

    Show the answer and explanation

    Answer: B

    A kubernetes.io/dockerconfigjson Secret listed under a ServiceAccount's imagePullSecrets is added to every Pod that uses that ServiceAccount, the default one included. You can also set imagePullSecrets per Pod.

    Why the other options are wrong

    • A. Runtimes don't read registry credentials from ConfigMaps.

    • C. Image pulls happen before containers run, so a mount inside them can't help.

    • D. The pull policy controls when to pull, not which credentials to use.

  2. Question 2Scheduling, Scaling and Rollouts

    An operator runs kubectl cordon node-7 and later the node becomes unreachable. Which two statements about the node-exporter DaemonSet Pod on node-7 are correct? (Choose two.)

    Choose 2.

    • A

      Cordoning does not stop the DaemonSet controller from running a Pod there

    • B

      It is not evicted after 300 seconds when the node is unreachable

    • C

      Cordoning immediately evicts it because the node is marked NoExecute

    • D

      It is rescheduled onto another node after 5 minutes

    • E

      It is evicted only if a PodDisruptionBudget allows it

    Show the answer and explanation

    Answer: A and B

    The DaemonSet controller adds tolerations so its Pods run on cordoned nodes and are never evicted for not-ready or unreachable conditions (NoExecute tolerations without tolerationSeconds). That keeps node agents such as log shippers and exporters in place.

    Why the other options are wrong

    • C. Cordon adds a NoSchedule taint, which evicts nothing.

    • D. DaemonSet Pods are tied to their node; they are never moved.

    • E. PDBs play no role here; these taints never trigger eviction for DaemonSet Pods.

  3. Question 3Operations and Extensibility

    A reconciler creates a Job every time it runs for a Report resource. After controller restarts and resyncs, duplicate Jobs appear. What is the right fix?

    • A

      Remember created Jobs in an in-memory map keyed by report name

    • B

      Look up the Job by a fixed name; create only if it's missing

    • C

      Handle only Create events and ignore Update and resync events

    • D

      Lower the workqueue rate limit so reconciles run less often

    Show the answer and explanation

    Answer: B

    Controllers are level-triggered: a reconcile can run many times for the same state, including after restarts and periodic resyncs. Each run should observe the actual state (does a Job with this name or label exist?) and act only on the difference. A deterministic name also makes a racing second create fail with AlreadyExists, and an owner reference lets garbage collection clean the Job up.

    Why the other options are wrong

    • A. In-memory state is lost on restart, which is exactly when duplicates appear.

    • C. Edge-triggered logic misses events that happen while the controller is down.

    • D. Fewer reconciles hide the race; they don't make creation idempotent.

  4. Question 4Core Concepts

    Your cluster's kube-apiserver runs v1.33. According to the Kubernetes version skew policy, which two statements are true? (Choose two.)

    Choose 2.

    • A

      A kubelet on v1.30 is still supported

    • B

      A kubelet must not be newer than the API server, so v1.34 is unsupported

    • C

      kube-controller-manager may run v1.34 ahead of the API server

    • D

      kubectl must be on exactly v1.33 to talk to this cluster

    • E

      A kubelet on v1.29 is supported as long as it is on the latest patch release

    Show the answer and explanation

    Answer: A and B

    Since v1.28 the policy lets kubelets be up to three minor versions older than kube-apiserver, but never newer. kube-controller-manager, kube-scheduler and cloud-controller-manager must not be newer than the API server and may be one minor older. kubectl is supported within one minor version either way. That is why upgrades go control plane first, then nodes.

    Why the other options are wrong

    • C. Controller manager and scheduler must not be newer than the API server they talk to.

    • D. kubectl is supported within one minor version, older or newer.

    • E. v1.29 is four minors behind, which is outside the skew policy.

  5. Question 5Running Applications

    Which manifest restores a VolumeSnapshot named orders-snap into a new volume?

    • A

      A VolumeSnapshotContent with source.volumeHandle set to the PVC name

    • B

      A PersistentVolume whose claimRef names orders-snap

    • C

      A PVC with dataSource: {kind: VolumeSnapshot, name: orders-snap}

    • D

      A VolumeSnapshotClass with restoreFrom: orders-snap

    Show the answer and explanation

    Answer: C

    To restore, create a new PVC whose dataSource references the VolumeSnapshot (apiGroup: snapshot.storage.k8s.io). The CSI driver provisions a fresh volume pre-populated with the snapshot data. The snapshot and the new PVC must be in the same namespace, and the requested size must be at least the snapshot's restore size.

    Why the other options are wrong

    • A. VolumeSnapshotContent represents a snapshot, not a restored volume.

    • B. claimRef binds a PV to a PVC, not to a snapshot.

    • D. There is no restoreFrom field; classes only configure snapshot creation.

  6. Question 6Scheduling, Scaling and Rollouts

    A high-priority Pod is Pending, and the scheduler decides to preempt lower-priority Pods on node N. Which statement is correct?

    • A

      The victims are killed instantly so that the new Pod can start right away

    • B

      Its status.nominatedNodeName is set to N, but it may land elsewhere

    • C

      The preemptor is bound to N immediately, before the victims exit

    • D

      Preemption always respects PodDisruptionBudgets of the victims

    Show the answer and explanation

    Answer: B

    When preemption succeeds, nominatedNodeName records node N, the victims are deleted with their graceful termination, and the preemptor waits. If another node becomes feasible first, the Pod may be scheduled there, so nominatedNodeName and nodeName can differ.

    Why the other options are wrong

    • A. Victims get their normal graceful termination period.

    • C. Binding happens only after resources are actually available.

    • D. PDBs are respected only on a best-effort basis during preemption.

  7. Question 7Operations and Extensibility

    A pod has been stuck in Terminating for an hour. Its node is healthy, and the pod's metadata contains:

    finalizers:
    - backup.example.com/snapshot

    The controller that owned this finalizer was uninstalled last week. What is happening?

    • A

      The grace period is too long; pods wait 1 hour by default

    • B

      Nothing can remove the pod until the finalizer is cleared

    • C

      The kubelet is still waiting for the liveness probe to pass

    • D

      The API server is overloaded and queuing the delete

    Show the answer and explanation

    Answer: B

    Deletion sets deletionTimestamp, but the API server only removes an object once its finalizers list is empty. A finalizer whose controller no longer exists will never be cleared, so the object stays Terminating. Restore the controller so it can finish its cleanup, or, if you understand the consequences, remove the finalizer with kubectl patch.

    Why the other options are wrong

    • A. The default grace period is 30 seconds, not an hour.

    • C. Probes don't gate deletion; the object stays because of the finalizer.

    • D. API load wouldn't hold one object for an hour while the cluster is healthy.

  8. Question 8Core Concepts

    A logging DaemonSet runs on every worker node but not on the kubeadm control-plane node. Why, and what fixes it?

    • A

      DaemonSets never run on control-plane nodes, by design

    • B

      The control-plane node needs label node-role=worker added

    • C

      Add nodeName for the control-plane node to the Pod template

    • D

      It has a NoSchedule taint; add a matching toleration

    Show the answer and explanation

    Answer: D

    kubeadm taints control-plane nodes with node-role.kubernetes.io/control-plane:NoSchedule. A DaemonSet creates one Pod per eligible node, and a node is only eligible if the Pod tolerates its taints. Add a toleration for that key (operator Exists, effect NoSchedule), as the official fluentd DaemonSet example does.

    Why the other options are wrong

    • A. They can; they just need to tolerate the control-plane taint.

    • B. Labels are not the blocker; the control-plane taint is.

    • C. A fixed nodeName would pin every daemon Pod to one node.

  9. Question 9Running Applications

    You create a ConfigMap with kubectl create configmap app --from-env-file=app.env, where app.env has three KEY=VALUE lines. What does the ConfigMap contain?

    • A

      One key, app.env, holding the whole file as text

    • B

      Three keys, one for each KEY=VALUE line

    • C

      Three keys whose values still include the KEY= prefix

    • D

      Nothing, because env files are only valid with envFrom

    Show the answer and explanation

    Answer: B

    --from-env-file reads KEY=VALUE lines (ignoring blank lines and # comments) and creates one key per line, while --from-file stores the whole file under a single key. Pair the result with envFrom to inject every key as a variable.

    Why the other options are wrong

    • A. That is what --from-file does; --from-env-file parses the lines.

    • C. The line is split at the first =; the prefix isn't kept in the value.

    • D. Env files are a supported input format for kubectl create configmap.

  10. Question 10Scheduling, Scaling and Rollouts

    GPU nodes are tainted gpu=true:NoSchedule. The ML Pods have a matching toleration, yet many of them land on ordinary CPU nodes. Why, and what fixes it?

    • A

      The taint is wrong; it should use NoExecute to pull tolerating Pods in

    • B

      Tolerations only allow a node; add a nodeSelector or node affinity too

    • C

      Tolerations need operator: Exists to take effect

    • D

      The scheduler prefers untainted nodes; lowering the CPU nodes' score fixes it

    Show the answer and explanation

    Answer: B

    Taints and tolerations repel: a toleration means "I may run on this tainted node", not "I must". To dedicate nodes, combine a taint (to keep other workloads off) with a nodeSelector or required node affinity on a node label (to keep these workloads on).

    Why the other options are wrong

    • A. NoExecute evicts untolerating Pods; it never attracts tolerating ones.

    • C. Equal with a value works; the operator does not attract Pods either.

    • D. Scoring tweaks would not guarantee placement on GPU nodes.

Practise all 450 K8S questions

Start with the free 15-question diagnostic. It shows where to focus, and your results carry over if you sign up.

Go to K8S